MCX issued a circular regarding the Cyber Security and Cyber Resilience Audit of Trading Members

Oct 09, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Multi Commodity Exchange of India Ltd. (MCX) on October 08, 2026, issued a circular regarding Cyber Security and Cyber Resilience Audit of Trading Members.

The following has been stated: -

•The Exchange has prescribed timelines and guidelines for conducting half-yearly Cyber Security and Cyber Resilience Audits of Trading Members under SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF). 

•Qualified REs and Mid-size/Small-size REs providing Internet-Based Trading (IBT) or algorithmic trading facilities must conduct the audit for the period ending September 30, 2026, through a CERT-In empanelled auditor and submit the report, approved by the IT Committee, by December 31, 2026, followed by the Action Taken Report (ATR)/revalidation report by March 31, 2027. 

•The audit must cover 100% of critical systems and 25% of non-critical systems, with the sampling rationale documented, and verify the entity’s SEBI-prescribed categorisation. 

•The report must include management comments, control-wise compliance status, justifications for non-applicable items and details of the audit scope and findings. 

•The submission facility will be available from October 25, 2026, and members must follow CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines; eligible NSE-registered members must submit cyber security incident details to NSE for sharing with other Exchanges.

[Circular No.: MCX/TECH/570/2026]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

✦ NEW  ·  AI ASSISTANT